38 lines
1.7 KiB
Bash
Executable File
38 lines
1.7 KiB
Bash
Executable File
#!/bin/bash
|
|
# Rewrite the auth FILES harnesses read their key from — and the base URL beside them —
|
|
# off the live .env, then exec "$@".
|
|
#
|
|
# codex reads its key from ${CODEX_HOME:-$HOME/.codex}/auth.json, which container-create
|
|
# wrote once from the .env of that moment — so a key rotated afterwards never reached it
|
|
# and needed a rebuild. claude needs none of this: it has an apiKeyHelper that re-reads
|
|
# .env per request. Interactive launches route through here so each one re-derives first.
|
|
#
|
|
# The base URL never rotates, so the case that matters is the one where container-create
|
|
# could not derive it at all (no .env yet) and wrote no config: the key then refreshes
|
|
# fine while codex still has no proxy URL and talks to the provider directly.
|
|
#
|
|
# Trials are unaffected either way: harbor-run re-derives OPENAI_API_KEY per invocation
|
|
# and harbor's codex agent authenticates the sandbox from that env var, not from this file.
|
|
set -uo pipefail
|
|
|
|
_scripts_dir="${HARNESS_SCRIPTS_DIR:-/workspace/scripts}"
|
|
|
|
# Subshell, and every failure swallowed: a refresh that cannot run must never stop the
|
|
# agent from starting. The auth file already on disk is the PREVIOUS key, not nothing, so
|
|
# failing open leaves the worker exactly where they were before this wrapper existed.
|
|
(
|
|
set -a
|
|
# shellcheck disable=SC1090
|
|
. "${RACCOON_ENV_FILE:-/workspace/.env}" 2>/dev/null || true
|
|
set +a
|
|
# shellcheck disable=SC1091
|
|
HARNESS_SCRIPTS_DIR="$_scripts_dir" . "$_scripts_dir/lib/harness-credentials.sh" || exit 0
|
|
harness_setup_credentials
|
|
harness_write_auth
|
|
harness_refresh_config_keys
|
|
) >/dev/null 2>&1 || true
|
|
|
|
# No args is a valid call: refresh only, for a lifecycle hook.
|
|
[ "$#" -gt 0 ] || exit 0
|
|
exec "$@"
|